Cloud & Productivity
Seven Microsoft 365 Security Settings Most Teams Miss
Microsoft 365 ships with sensible defaults for convenience, not for security. These are the tenant settings we change on day one.

Defaults optimise for adoption
Microsoft configures a new tenant so that everything works immediately for everyone. That is the right call for onboarding and the wrong call for a business holding client financial or health data.
The following changes take an afternoon and remove a large share of the attack surface we see exploited in real incidents.
The settings we change first
- Block legacy authentication protocols that bypass MFA entirely.
- Enforce conditional access by device compliance and location risk.
- Disable automatic external mail forwarding at the tenant level.
- Restrict who can consent to third-party OAuth applications.
- Turn on unified audit logging and retain it long enough to investigate.
- Apply Safe Links and Safe Attachments to every mailbox, not a pilot group.
- Review and time-limit global administrator accounts; use separate admin identities.
Then verify, quarterly
Tenant configuration drifts. New services get enabled, contractors get exceptions, and a policy that was correct in January is full of holes by June. Put a recurring configuration review on the calendar and treat the output as a report to leadership, not a technician's note.



